elk 安装参见
https://blog.csdn.net/wanchaopeng/article/details/116270837
logstash使用一个名叫FileWaatch的Ruby Gem库来监听文件变化,这个库支持Glob展开文件路径,而且会记录一个叫.sincedbd 数据库文件来跟踪监听的日志文件的当前读取位置。
1. 配置展示 #input
input {
beats {
port => 5044
}
file {
path => ["/usr/local/nginx/logs/jenkins/access.log","/usr/local/nginx/logs/omo-crm/access.log"]
type => "nginx1"
start_position => "beginning"
}
}
filewatch配置项:
2. output 的输出配置
output {
elasticsearch {
hosts => ["172.17.10.29:9200"]
}
stdout { codec => rubydebug }
}